CVE-2026-15581
Received Received - Intake

TrustyAI Service Authentication Bypass Vulnerability

Vulnerability report for CVE-2026-15581, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: Red Hat, Inc.

Description

A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. An attacker can exploit this to read, tamper with, or delete monitoring data and configurations, and inject arbitrary data into the service, potentially disrupting tenant operations.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authentication bypass flaw in the TrustyAI Service (TAS) deployment. It allows any pod on the cluster network to access the TAS backend API without proper authentication. An attacker can exploit this to read, modify, or delete monitoring data and configurations, and inject arbitrary data into the service.

Impact Analysis

An attacker could disrupt tenant operations by tampering with monitoring data or configurations. They could also read sensitive data, delete critical information, or inject malicious data into the service, potentially causing operational failures or data corruption.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR and HIPAA requirements for data protection and access controls. It may result in non-compliance due to potential data breaches or unauthorized modifications to regulated data.

Mitigation Strategies

Restrict network access to the TrustyAI Service (TAS) backend API to prevent unauthorized pods from reaching it. Review and update pod network policies to block external access. Monitor API logs for unusual activity indicating attempts to bypass authentication.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15581. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart